Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2009-3743

Опубликовано: 24 авг. 2010
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 3ghostscriptNot affected
Red Hat Enterprise Linux 4ghostscriptNot affected
Red Hat Enterprise Linux 5ghostscriptFixedRHSA-2012:009502.02.2012
Red Hat Enterprise Linux 6ghostscriptFixedRHSA-2012:009502.02.2012

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=627902ghostscript: TrueType bytecode intepreter integer overflow or wraparound

EPSS

Процентиль: 91%
0.06694
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
почти 15 лет назад

Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.

nvd
почти 15 лет назад

Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.

debian
почти 15 лет назад

Off-by-one error in the Ins_MINDEX function in the TrueType bytecode i ...

github
больше 3 лет назад

Off-by-one error in the Ins_MINDEX function in the TrueType bytecode interpreter in Ghostscript before 8.71 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a malformed TrueType font in a document that trigger an integer overflow and a heap-based buffer overflow.

oracle-oval
больше 13 лет назад

ELSA-2012-0095: ghostscript security update (MODERATE)

EPSS

Процентиль: 91%
0.06694
Низкий

4.3 Medium

CVSS2